This page lists the IAM roles and permissions for Certificate Manager. To search through all roles and permissions, see the role and permission index .
Certificate Manager roles
Certificatemanager Admin
( roles/
)
Admin role for certificatemanager
certificatemanager.*
-
certificatemanager.certissuanceconfigs. create -
certificatemanager.certissuanceconfigs. createTagBinding -
certificatemanager.certissuanceconfigs. delete -
certificatemanager.certissuanceconfigs. deleteTagBinding -
certificatemanager.certissuanceconfigs. get -
certificatemanager.certissuanceconfigs. list -
certificatemanager.certissuanceconfigs. listEffectiveTags -
certificatemanager.certissuanceconfigs. listTagBindings -
certificatemanager.certissuanceconfigs. update -
certificatemanager.certissuanceconfigs. use -
certificatemanager.certmapentries. create -
certificatemanager.certmapentries. createTagBinding -
certificatemanager.certmapentries. delete -
certificatemanager.certmapentries. deleteTagBinding -
certificatemanager.certmapentries. get -
certificatemanager.certmapentries. list -
certificatemanager.certmapentries. listEffectiveTags -
certificatemanager.certmapentries. listTagBindings -
certificatemanager.certmapentries. update -
certificatemanager.certmaps. create -
certificatemanager.certmaps. createTagBinding -
certificatemanager.certmaps. delete -
certificatemanager.certmaps. deleteTagBinding -
certificatemanager.certmaps. get -
certificatemanager.certmaps. list -
certificatemanager.certmaps. listEffectiveTags -
certificatemanager.certmaps. listTagBindings -
certificatemanager.certmaps. update -
certificatemanager.certmaps. use -
certificatemanager.certs. create -
certificatemanager.certs. createTagBinding -
certificatemanager.certs. delete -
certificatemanager.certs. deleteTagBinding -
certificatemanager.certs.get -
certificatemanager.certs.list -
certificatemanager.certs. listEffectiveTags -
certificatemanager.certs. listTagBindings -
certificatemanager.certs. update -
certificatemanager.certs.use -
certificatemanager.dnsauthorizations. create -
certificatemanager.dnsauthorizations. createTagBinding -
certificatemanager.dnsauthorizations. delete -
certificatemanager.dnsauthorizations. deleteTagBinding -
certificatemanager.dnsauthorizations. get -
certificatemanager.dnsauthorizations. list -
certificatemanager.dnsauthorizations. listEffectiveTags -
certificatemanager.dnsauthorizations. listTagBindings -
certificatemanager.dnsauthorizations. update -
certificatemanager.dnsauthorizations. use -
certificatemanager.locations. get -
certificatemanager.locations. list -
certificatemanager.observedcerts. get -
certificatemanager.observedcerts. list -
certificatemanager.operations. cancel -
certificatemanager.operations. delete -
certificatemanager.operations. get -
certificatemanager.operations. list -
certificatemanager.trustconfigs. create -
certificatemanager.trustconfigs. createTagBinding -
certificatemanager.trustconfigs. delete -
certificatemanager.trustconfigs. deleteTagBinding -
certificatemanager.trustconfigs. get -
certificatemanager.trustconfigs. list -
certificatemanager.trustconfigs. listEffectiveTags -
certificatemanager.trustconfigs. listTagBindings -
certificatemanager.trustconfigs. update -
certificatemanager.trustconfigs. use
resourcemanager.projects.get
resourcemanager.projects.list
Certificate Manager Editor
( roles/
)
Edit access to Certificate Manager all resources.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.certs.get
certificatemanager.certs.list
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.certs.use
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.locations.*
-
certificatemanager.locations. get -
certificatemanager.locations. list
certificatemanager.
-
certificatemanager.observedcerts. get -
certificatemanager.observedcerts. list
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Certificate Manager Viewer
( roles/
)
Read-only access to Certificate Manager all resources.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.certs.get
certificatemanager.certs.list
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.locations.*
-
certificatemanager.locations. get -
certificatemanager.locations. list
certificatemanager.
-
certificatemanager.observedcerts. get -
certificatemanager.observedcerts. list
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
certificatemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Certificate Manager Owner
( roles/
)
Full access to Certificate Manager all resources.
certificatemanager.*
-
certificatemanager.certissuanceconfigs. create -
certificatemanager.certissuanceconfigs. createTagBinding -
certificatemanager.certissuanceconfigs. delete -
certificatemanager.certissuanceconfigs. deleteTagBinding -
certificatemanager.certissuanceconfigs. get -
certificatemanager.certissuanceconfigs. list -
certificatemanager.certissuanceconfigs. listEffectiveTags -
certificatemanager.certissuanceconfigs. listTagBindings -
certificatemanager.certissuanceconfigs. update -
certificatemanager.certissuanceconfigs. use -
certificatemanager.certmapentries. create -
certificatemanager.certmapentries. createTagBinding -
certificatemanager.certmapentries. delete -
certificatemanager.certmapentries. deleteTagBinding -
certificatemanager.certmapentries. get -
certificatemanager.certmapentries. list -
certificatemanager.certmapentries. listEffectiveTags -
certificatemanager.certmapentries. listTagBindings -
certificatemanager.certmapentries. update -
certificatemanager.certmaps. create -
certificatemanager.certmaps. createTagBinding -
certificatemanager.certmaps. delete -
certificatemanager.certmaps. deleteTagBinding -
certificatemanager.certmaps. get -
certificatemanager.certmaps. list -
certificatemanager.certmaps. listEffectiveTags -
certificatemanager.certmaps. listTagBindings -
certificatemanager.certmaps. update -
certificatemanager.certmaps. use -
certificatemanager.certs. create -
certificatemanager.certs. createTagBinding -
certificatemanager.certs. delete -
certificatemanager.certs. deleteTagBinding -
certificatemanager.certs.get -
certificatemanager.certs.list -
certificatemanager.certs. listEffectiveTags -
certificatemanager.certs. listTagBindings -
certificatemanager.certs. update -
certificatemanager.certs.use -
certificatemanager.dnsauthorizations. create -
certificatemanager.dnsauthorizations. createTagBinding -
certificatemanager.dnsauthorizations. delete -
certificatemanager.dnsauthorizations. deleteTagBinding -
certificatemanager.dnsauthorizations. get -
certificatemanager.dnsauthorizations. list -
certificatemanager.dnsauthorizations. listEffectiveTags -
certificatemanager.dnsauthorizations. listTagBindings -
certificatemanager.dnsauthorizations. update -
certificatemanager.dnsauthorizations. use -
certificatemanager.locations. get -
certificatemanager.locations. list -
certificatemanager.observedcerts. get -
certificatemanager.observedcerts. list -
certificatemanager.operations. cancel -
certificatemanager.operations. delete -
certificatemanager.operations. get -
certificatemanager.operations. list -
certificatemanager.trustconfigs. create -
certificatemanager.trustconfigs. createTagBinding -
certificatemanager.trustconfigs. delete -
certificatemanager.trustconfigs. deleteTagBinding -
certificatemanager.trustconfigs. get -
certificatemanager.trustconfigs. list -
certificatemanager.trustconfigs. listEffectiveTags -
certificatemanager.trustconfigs. listTagBindings -
certificatemanager.trustconfigs. update -
certificatemanager.trustconfigs. use
resourcemanager.projects.get
resourcemanager.projects.list
Service agent roles
Service agent roles should only be granted to service agents .
| Role | Permissions |
|---|---|
Certificate Manager Service Agent( Grants Certificate Manager access to services and APIs in the user project. |
|
Certificate Manager permissions
certificatemanager.
certissuanceconfigs.
create
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certissuanceconfigs.
createTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
certissuanceconfigs.
delete
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certissuanceconfigs.
deleteTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
certissuanceconfigs.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certissuanceconfigs.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Certificate Manager Owner
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certissuanceconfigs.
listEffectiveTags
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certissuanceconfigs.
listTagBindings
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certissuanceconfigs.
update
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certissuanceconfigs.
use
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmapentries.
create
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmapentries.
createTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
certmapentries.
delete
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmapentries.
deleteTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
certmapentries.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmapentries.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Certificate Manager Owner
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmapentries.
listEffectiveTags
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmapentries.
listTagBindings
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmapentries.
update
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmaps.
create
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmaps.
createTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
certmaps.
delete
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmaps.
deleteTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
certmaps.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Compute Load Balancer Admin
( roles/
)
Certificate Manager Owner
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmaps.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Compute Load Balancer Admin
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Certificate Manager Owner
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmaps.
listEffectiveTags
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmaps.
listTagBindings
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmaps.
update
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certmaps.
use
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Compute Load Balancer Admin
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certs.
create
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certs.
createTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
certs.
delete
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certs.
deleteTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.certs.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.certs.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Certificate Manager Owner
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Audit Manager Auditing Service Agent
(
roles/)auditmanager.serviceAgent - Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certs.
listEffectiveTags
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certs.
listTagBindings
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
certs.
update
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.certs.use
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
dnsauthorizations.
create
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
dnsauthorizations.
createTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
dnsauthorizations.
delete
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
dnsauthorizations.
deleteTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
dnsauthorizations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
dnsauthorizations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Certificate Manager Owner
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
dnsauthorizations.
listEffectiveTags
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
dnsauthorizations.
listTagBindings
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
dnsauthorizations.
update
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
dnsauthorizations.
use
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
locations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
Support User
( roles/
)
Service agent roles
- Certificate Manager Service Agent
(
roles/)certificatemanager.serviceAgent
certificatemanager.
locations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Certificate Manager Owner
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
certificatemanager.
observedcerts.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
Support User
( roles/
)
certificatemanager.
observedcerts.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Certificate Manager Owner
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
certificatemanager.
operations.
cancel
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Owner
( roles/
)
certificatemanager.
operations.
delete
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Owner
( roles/
)
certificatemanager.
operations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
Support User
( roles/
)
Service agent roles
- Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
operations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Certificate Manager Owner
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
certificatemanager.
trustconfigs.
create
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
trustconfigs.
createTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
trustconfigs.
delete
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
trustconfigs.
deleteTagBinding
Owner
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Tag User
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
certificatemanager.
trustconfigs.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
trustconfigs.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Certificate Manager Owner
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Audit Manager Auditing Service Agent
(
roles/)auditmanager.serviceAgent - Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
trustconfigs.
listEffectiveTags
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent
certificatemanager.
trustconfigs.
listTagBindings
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Certificate Manager Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent
certificatemanager.
trustconfigs.
update
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent
certificatemanager.
trustconfigs.
use
Owner
( roles/
)
Editor
( roles/
)
Certificatemanager Admin
( roles/
)
Certificate Manager Editor
( roles/
)
Certificate Manager Owner
( roles/
)
Service agent roles
- Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent

